Junglewise Threat Intelligence

CVE-2024-7042: LangChain Community SQL injection in GraphCypherQAChain

CVE-2024-7042 · Severity: low · CVSS 3 · Published 2024-10-29

Technologies: @langchain/community (npm). Vendors: npm, LangChain.

Executive brief

LangChain Community is a JavaScript library that provides integrations for AI applications with various data sources and services. A prompt injection vulnerability in the GraphCypherQAChain component allows attackers to bypass security controls and execute arbitrary database operations, leading to unauthorized data access, modification, deletion, and potential cross-tenant data breaches in multi-tenant systems.

Technical details

The GraphCypherQAChain class in @langchain/community versions 0.2.5 and earlier is vulnerable to prompt injection attacks that can be leveraged to execute SQL injection. The vulnerability exists in how user input is processed without proper sanitization before being passed to database queries. An attacker can craft malicious prompts that escape the intended query logic, allowing them to create, update, or delete database nodes and relationships, extract sensitive information, or deny service by deleting data. The vulnerability affects all systems using the vulnerable class and is particularly dangerous in multi-tenant environments where data isolation is critical. A fix was released in version 0.3.3.

Affected products

  • LangChain @langchain/community 0.2.5 and all earlier versions; fixed in 0.3.3

Timeline

  • 2024-10-29: disclosed
  • 2024-09-17: patched: Fix commit 615b9d9ab30a2d23a2f95fb8d7acfdf4b41ad7a6 authored on this date

References

Related threats